Executable labs for practitioners building the cyber risk lifecycle as a data system. These labs show how operational evidence can become reviewable risk knowledge—not another spreadsheet that waits for an annual assessment.
| Lab | Question | Status |
|---|---|---|
| 01 · Continuous risk identification | Can changing system evidence identify a risk condition and express it in business terms? | Learning prototype |
Run Lab 01 in one click with Binder, or use the lab's Docker path when you need a pinned local environment. Binder replay uses synthetic data and does not require an API key. Live LLM mode remains local by design.
- Lab 02 · Emerging risk discovery — expand beyond the known offboarding scenario using temporal evidence graphs and weak-signal research.
- Lab 03 · Risk analysis — estimate likelihood and consequence only after a scenario has passed human review.
- Lab 04 · Risk response — connect approved treatment decisions to owners, controls and measurable work.
- Lab 05 · Continuous monitoring — detect material changes in accepted scenarios, assumptions and treatments.
The roadmap is directional, not a release commitment. Each lab will keep raw evidence, transformations, model output and human decisions visibly separate.
Released under the MIT License.